CSIDB logo
Incident

Machatt Co., Ltd.

Incident posture

Attack window
Apr 2022
Location
Japan
Status
Historical
CIA posture
Available to members
Updated
2025-10-19 00:00

Linked entities

Victim
Machatt Co., Ltd.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Machatt Co., Ltd. experienced a data breach involving unauthorized third-party access to its online store, potentially compromising personal information of up to 16,093 customers. The confirmed exposed data included cardholder names, credit card numbers, validity terms, and security codes, while unauthorized access to other personal information in the database remained unverified. The company strengthened system security and monitoring following the incident, reporting it to relevant authorities including the Personal Information Protection Commission and local police.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Machatt Co., Ltd. identified unauthorized third-party access to its online store systems, potentially compromising the personal information of 16,093 customers. The breach involved sensitive credit card details, including cardholder names, credit card numbers, expiration dates, and security codes. While the company confirmed the exposure of payment card data, it could not verify whether attackers accessed additional personal information stored in the same database. Machatt detected the intrusion prior to April 21, 2022, when it filed an initial report with local law enforcement. The incident prompted formal notification to Japan's Personal Information Protection Commission on April 27, 2022, indicating regulatory compliance efforts within six days of police reporting.

Public disclosure occurred nearly a month after regulatory notifications, with Machatt issuing an official breach notice on May 18, 2022. The company acknowledged system security deficiencies that permitted unauthorized database access but did not specify the intrusion methods or duration of undetected access. Response measures focused on infrastructure hardening based on internal investigation findings, with commitments to enhance monitoring capabilities and security protocols to prevent recurrence. No evidence suggested misuse of exposed financial data at the time of disclosure. The breach exclusively impacted customers of Machatt's online retail platform, though the company did not disclose whether affected individuals received direct notifications beyond the public announcement. Machatt's statement emphasized containment through post-incident security upgrades while maintaining operational continuity for its e-commerce services.

Sources

Sources available to members: 1 source.

CSIDB